CVE-2018-8637: Microsoft Windows 10
Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass, aka "Win32k Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
Affected products
- Microsoft Windows 10: version 1803 only; version 1809 only
- Microsoft Windows Server 2016: version 1803 only
- Microsoft Windows Server 2019: affected versions not specified
Published 2018-12-12. Last modified 2026-06-17.